Executive Summary
In August 2026, cybersecurity researchers Talal Haj Bakry and Tommy Mysk disclosed a vulnerability in Apple's iCloud Private Relay, a feature designed to enhance user privacy by routing Safari web traffic through dual relays. The flaw resides in WebKit's handling of DNS prefetching, WebAuthn Related Origin Requests, and WebTransport, which can bypass configured proxies and expose users' real IP addresses. This issue affects Safari and all third-party browsers on iOS, iPadOS, and macOS that rely on WebKit's proxy configuration APIs. As a result, users' actual IP addresses can be leaked, undermining the privacy protections offered by iCloud Private Relay.
This vulnerability is particularly concerning given the widespread use of WebKit across Apple's ecosystem and its integration into various browsers. The exposure of real IP addresses can lead to targeted attacks, tracking, and a compromise of user anonymity. Organizations and individuals relying on iCloud Private Relay for privacy should be aware of this flaw and consider additional protective measures until a patch is released.
Why This Matters Now
The disclosure of this vulnerability highlights the critical need for continuous scrutiny of privacy tools, especially those integrated into widely used platforms. As users increasingly rely on features like iCloud Private Relay to safeguard their online activities, vulnerabilities that expose real IP addresses can have significant privacy implications. Immediate attention and remediation are essential to maintain user trust and security.
Attack Path Analysis
An attacker exploits vulnerabilities in WebKit features to bypass iCloud Private Relay, exposing the user's real IP address. This exposure allows the attacker to gather network information and potentially escalate privileges. With the real IP address, the attacker can move laterally within the network, establish command and control channels, exfiltrate sensitive data, and cause significant impact.
Kill Chain Progression
Initial Compromise
Description
An attacker exploits vulnerabilities in WebKit features such as DNS prefetching, WebAuthn Related Origin Requests, and WebTransport to bypass iCloud Private Relay, exposing the user's real IP address.
MITRE ATT&CK® Techniques
Proxy
System Binary Proxy Execution
Browser Session Hijacking
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing firewalls are documented, in use, and known to all affected parties.
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Network and Environment
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
WebKit proxy bypasses expose real IP addresses during financial transactions, compromising customer privacy and potentially violating PCI compliance requirements for encrypted traffic protection.
Health Care / Life Sciences
iCloud Private Relay vulnerabilities leak patient IP addresses through WebAuthn and DNS prefetching, violating HIPAA 164.312(e)(1) encryption requirements for protected health information transmission.
Banking/Mortgage
WebKit-based browser vulnerabilities expose customer IP addresses during online banking sessions, undermining zero trust segmentation and encrypted traffic controls mandated by financial regulations.
Information Technology/IT
WebKit proxy bypass vulnerabilities affect all iOS/iPadOS browsers, compromising enterprise zero trust architectures and multicloud visibility controls across IT infrastructure and cloud environments.
Sources
- Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasseshttps://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.htmlVerified
- IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relayhttps://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/Verified
- About iCloud Private Relayhttps://support.apple.com/en-us/102602Verified
- iCloud Private Relay flaw leaks users' IP addresseshttps://appleinsider.com/articles/21/09/25/icloud-private-relay-flaw-leaks-users-ip-addressesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to exploit the exposed IP address, thereby reducing the potential for lateral movement and data exfiltration.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit the exposed IP address would likely be constrained, limiting their capacity to gather network information and escalate privileges.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be limited due to restricted access to sensitive systems.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the network would likely be constrained, reducing their ability to access additional systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command and control channels would likely be restricted, reducing persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely be limited, reducing data loss.
The attacker's ability to cause significant impact would likely be constrained, reducing potential damage to services and data.
Impact at a Glance
Affected Business Functions
- User Privacy Protection
- Anonymized Browsing Services
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of users' real IP addresses and DNS queries, compromising anonymity and privacy.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Encrypted Traffic (HPE) to ensure all data in transit is encrypted, mitigating the risk of data exposure.
- • Deploy Zero Trust Segmentation to enforce least privilege access and limit lateral movement within the network.
- • Utilize Multicloud Visibility & Control to monitor and manage traffic across all cloud environments, detecting anomalous interactions.
- • Apply Egress Security & Policy Enforcement to control outbound traffic and prevent unauthorized data exfiltration.
- • Integrate Threat Detection & Anomaly Response systems to identify and respond to suspicious activities promptly.



